Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Content] Add Investigation Guides to Linux Persistence Rules - 1 #3288

Merged
merged 6 commits into from
Dec 11, 2023

Conversation

Aegrah
Copy link
Contributor

@Aegrah Aegrah commented Nov 22, 2023

Summary

This rule adds Investigation Guides for 4 persistence related Linux rules. Due to PTO I will split this task up in 2 PRs. The next PR will add 6 more.

@Aegrah Aegrah merged commit 6c614eb into main Dec 11, 2023
11 checks passed
@Aegrah Aegrah deleted the linux-investigation-guides-part-2 branch December 11, 2023 12:53
protectionsmachine pushed a commit that referenced this pull request Dec 11, 2023
…s - 1 (#3288)

* [Security Content] Add IGs to Persistence Rules

* Cleaned query

* IG description fix

* Added related rules

---------

Co-authored-by: Terrance DeJesus <[email protected]>

Removed changes from:
- rules/linux/persistence_cron_job_creation.toml
- rules/linux/persistence_systemd_service_creation.toml

(selectively cherry picked from commit 6c614eb)
protectionsmachine pushed a commit that referenced this pull request Dec 11, 2023
…s - 1 (#3288)

* [Security Content] Add IGs to Persistence Rules

* Cleaned query

* IG description fix

* Added related rules

---------

Co-authored-by: Terrance DeJesus <[email protected]>

Removed changes from:
- rules/linux/persistence_cron_job_creation.toml
- rules/linux/persistence_systemd_service_creation.toml

(selectively cherry picked from commit 6c614eb)
protectionsmachine pushed a commit that referenced this pull request Dec 11, 2023
…s - 1 (#3288)

* [Security Content] Add IGs to Persistence Rules

* Cleaned query

* IG description fix

* Added related rules

---------

Co-authored-by: Terrance DeJesus <[email protected]>

Removed changes from:
- rules/linux/persistence_cron_job_creation.toml
- rules/linux/persistence_systemd_service_creation.toml

(selectively cherry picked from commit 6c614eb)
protectionsmachine pushed a commit that referenced this pull request Dec 11, 2023
…s - 1 (#3288)

* [Security Content] Add IGs to Persistence Rules

* Cleaned query

* IG description fix

* Added related rules

---------

Co-authored-by: Terrance DeJesus <[email protected]>

(cherry picked from commit 6c614eb)
protectionsmachine pushed a commit that referenced this pull request Dec 11, 2023
…s - 1 (#3288)

* [Security Content] Add IGs to Persistence Rules

* Cleaned query

* IG description fix

* Added related rules

---------

Co-authored-by: Terrance DeJesus <[email protected]>

(cherry picked from commit 6c614eb)
protectionsmachine pushed a commit that referenced this pull request Dec 11, 2023
…s - 1 (#3288)

* [Security Content] Add IGs to Persistence Rules

* Cleaned query

* IG description fix

* Added related rules

---------

Co-authored-by: Terrance DeJesus <[email protected]>

(cherry picked from commit 6c614eb)
protectionsmachine pushed a commit that referenced this pull request Dec 11, 2023
…s - 1 (#3288)

* [Security Content] Add IGs to Persistence Rules

* Cleaned query

* IG description fix

* Added related rules

---------

Co-authored-by: Terrance DeJesus <[email protected]>

(cherry picked from commit 6c614eb)
protectionsmachine pushed a commit that referenced this pull request Dec 11, 2023
…s - 1 (#3288)

* [Security Content] Add IGs to Persistence Rules

* Cleaned query

* IG description fix

* Added related rules

---------

Co-authored-by: Terrance DeJesus <[email protected]>

(cherry picked from commit 6c614eb)
protectionsmachine pushed a commit that referenced this pull request Dec 11, 2023
…s - 1 (#3288)

* [Security Content] Add IGs to Persistence Rules

* Cleaned query

* IG description fix

* Added related rules

---------

Co-authored-by: Terrance DeJesus <[email protected]>

(cherry picked from commit 6c614eb)
@Aegrah Aegrah restored the linux-investigation-guides-part-2 branch December 19, 2023 08:43
@Aegrah Aegrah deleted the linux-investigation-guides-part-2 branch December 19, 2023 08:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants